JobVault never charges job seekers. Learn how to stay safe →
Back to all jobs
Infrastructure
full time

Senior Security Engineer, Bug Bounty

mozillaRemote

Salary

R68 000 – R91 000 per month

Job Type

full time

Posted

about 1 hour ago

Closing date

26 Sep 2026

Share:WhatsAppLinkedIn

Job Description

Mozilla, a company dedicated to a healthy, open internet, is seeking a skilled Senior Security Engineer to take charge of its Web Bug Bounty Programme. This pivotal role is focused on protecting users by proactively identifying and mitigating security risks within Mozilla's products. If you are passionate about security, have a knack for finding vulnerabilities, and excel at building relationships within the security community, this remote opportunity could be an excellent fit for you.

The organisation champions the internet as a universal public good, and this role directly contributes to that mission by ensuring the safety and privacy of millions of users worldwide. You will be at the forefront of defending the integrity of Mozilla's offerings, from the widely used Firefox browser to emerging technologies. This position requires a blend of technical expertise, strategic thinking, and excellent interpersonal skills, allowing you to make a significant impact on the security posture of a globally recognised tech entity.

About the Role

As the steward of Mozilla's Web Bug Bounty Programme, you will be responsible for its entire lifecycle. This includes devising and implementing the programme's overarching strategy, defining key performance indicators (KPIs) to measure success, and continually seeking avenues for enhancement. You will also serve as the primary point of contact for external security researchers and any relevant platforms they may use, nurturing a community built on trust and high-quality contributions. Your efforts will be instrumental in encouraging ethical hacking and ensuring that valuable security insights are brought to Mozilla's attention. This involves managing the intake of vulnerability reports from various channels, including dedicated platforms, bug tracking systems, and direct email submissions.

Key Responsibilities

Your day-to-day responsibilities will be multifaceted and critical to the programme's effectiveness:

  • **Programme Management:** Own and scale the Web Bug Bounty Programme, encompassing strategy, prioritization, and performance metrics.
  • **Researcher Engagement:** Act as the main liaison with external vulnerability researchers and bug bounty platforms, fostering a productive and reliable community.
  • **Vulnerability Triage and Validation:** Lead the process of assessing and technically verifying incoming vulnerability reports from multiple sources.
  • **Remediation Coordination:** Drive the end-to-end process of addressing identified vulnerabilities, working closely with engineering teams to ensure prompt and effective fixes.
  • **Root Cause Analysis:** Identify underlying causes of security flaws and systemic issues, influencing long-term improvements in secure development practices across the organisation.
  • **Incident Response Collaboration:** Partner with the Security Incident Response Team (SIRT) during active security incidents and contribute to post-incident reviews.
  • **Code Review:** Conduct targeted code reviews, primarily focusing on JavaScript and Python, during investigations and when assessing high-risk system changes.
  • **Tool Development:** Develop or leverage existing tools to enhance the efficiency of vulnerability triage, improve signal quality, and gain deeper insights into programme trends.

What They're Looking For

To be successful in this role, you should possess a strong foundation in security engineering, coupled with practical experience in managing and running bug bounty initiatives. Key qualifications include:

  • A minimum of three years of experience in a dedicated security engineering capacity.
  • Proven experience in operating bug bounty programmes, including strategies for scaling, automation, and enhancements, or significant experience as a bug bounty hunter.
  • Hands-on experience with modern cloud technologies, such as Amazon Web Services (AWS), Google Cloud Platform (GCP), Heroku, or Microsoft Azure.
  • Demonstrated ability to analyse software and systems to move beyond identifying vulnerabilities towards understanding root causes and implementing preventative measures.
  • Real-world experience in software development or engineering operations.
  • Proficiency or a strong aptitude for developing custom tools in various programming languages like Python, Go, Rust, or JavaScript, while not strictly mandatory, is highly advantageous.
  • Excellent communication, collaboration, and problem-solving skills, with the capacity to influence and guide cross-functional teams effectively.

Mozilla values demonstrable skills and experience over formal qualifications. A curious mind, a passion for security, and a commitment to continuous learning are highly prized.

In South Africa, senior security engineering roles involving programme management and incident response often command competitive salaries, reflecting the critical nature of these positions. Employers range from large multinational tech firms with local offices to established South African corporations in finance, telecommunications, and e-commerce, as well as specialised cybersecurity consultancies. Career progression typically involves moving into lead security architect positions, management roles within security operations, or specialisation in areas like application security or threat intelligence.

Requirements

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting.
  • Practical experience working with modern cloud technologies (e.g., Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.).
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention.
  • Real-world experience in software development and/or engineering operations.
  • Ability to develop your own tools as needed in a variety of programming languages (e.g., Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

About the employer

M

mozilla

mozilla is a hiring organisation operating in Remote within the infrastructure sector. They are currently recruiting for the Senior Security Engineer, Bug Bounty role advertised on this page. Visit the official application link for more about the company, its culture and the team you would be joining.

Interested in this role at mozilla?

JobVault never charges job seekers to apply.

Apply Now

Get ready for your application

Free career guides written for South African job seekers.

Browse all career resources →